CISA Warns Hackers Are Exploiting Critical Ray Framework Flaw
Ray is an open-source distributed computing framework widely used to scale artificial intelligence and machine-learning workloads across clusters. A security breach in such infrastructure can expose valuable models, data and computing resources, while potentially giving attackers a foothold across multiple connected systems. That makes vulnerabilities in Ray particularly significant for companies and research teams operating shared or internet-accessible AI environments.
The US Cybersecurity and Infrastructure Security Agency said hackers are actively exploiting CVE-2025-62593, a code-injection flaw in Ray, and added it to its Known Exploited Vulnerabilities catalog. The vulnerability carries a CVSS severity score of 9.4. Ray’s maintainers addressed the issue in version 2.52.0, raising pressure on users to upgrade promptly and review affected systems for signs of unauthorized activity.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →